Privacy Policy
Effective Date: April 16, 2026
1. Introduction
Clock Deck LLC ("Company," "we," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our time tracking and workforce management platform ("Service"). By using the Service, you consent to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password, business name, and role when you create an account.
- Billing Information: Payment card details are collected and processed directly by our PCI-compliant payment processor. We do not store your full card number, CVV, or expiry date on our servers. We retain only a tokenized reference for recurring billing.
- Business Data: Employee names, schedules, time entries, timesheets, and other workforce management data you enter into the Service.
2.2 Information Collected Automatically
- Device & Browser Information: IP address, browser type, operating system, and device identifiers.
- Usage Data: Pages viewed, features used, timestamps, and interaction patterns.
- Location Data: GPS coordinates collected during clock-in/clock-out events when GPS verification is enabled by the business administrator. Location data is collected only during clock events, not continuously.
- Photo Data: Selfie photos captured during clock-in events when photo verification is enabled by the business administrator.
3. How We Use Your Information
- Provide the Service: Process time entries, generate timesheets, manage schedules, and administer your account.
- Billing: Process subscription payments, send invoices, and manage your billing cycle.
- Communication: Send account-related notifications, billing receipts, and important service updates.
- Security: Detect and prevent fraud, unauthorized access, and abuse of the Service.
- Improvement: Analyze usage patterns to improve features, performance, and user experience.
- Legal Compliance: Comply with applicable laws, regulations, and legal processes.
4. GPS & Photo Data
GPS location data and photo verification data are sensitive categories that receive additional protections:
- These features are opt-in and must be explicitly enabled by the business administrator.
- GPS data is collected only at the moment of clock-in/clock-out, not continuously or in the background.
- Photo data is used solely for identity verification during clock events.
- Business administrators are responsible for informing their employees about the use of these features and obtaining any required consents under applicable laws.
- This data is stored securely and is accessible only to authorized business administrators.
5. Data Sharing & Disclosure
We do not sell your personal information. We may share data in the following circumstances:
- Service Providers: We use third-party infrastructure and service providers for database hosting, payment processing, and other operational needs. These providers process data on our behalf under strict confidentiality agreements and are contractually obligated to protect your information.
- Third-Party Integrations: If you choose to connect third-party services (such as accounting software), data necessary for that integration may be shared with the connected service in accordance with their own privacy policies. You control which integrations are enabled.
- Business Administrators: Employee data (time entries, GPS, photos) is accessible to authorized administrators within the employee's business.
- Agency Accounts: Agency/CPA account holders can view data for client businesses they manage.
- Legal Requirements: We may disclose information if required by law, subpoena, court order, or government request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
6. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS/SSL) and at rest
- Row-level security (RLS) ensuring multi-tenant data isolation
- Secure authentication with hashed passwords
- PCI-compliant payment processing through our certified payment processor (we never handle raw card data)
- Regular security reviews and access controls
No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
7. Data Retention
- Account Data: Retained for the duration of your account and for a reasonable period after closure for legal and business purposes.
- Time & Attendance Records: Retained in accordance with applicable labor law record-keeping requirements (typically 3–7 years depending on jurisdiction).
- Billing Records: Retained as required by tax and accounting regulations.
- GPS & Photo Data: Retained for the duration specified by the business administrator or as required by law.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Data Portability: Request your data in a commonly used, machine-readable format.
- Opt-Out: Opt out of non-essential communications.
To exercise these rights, contact us at support@clockdeck.com.
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
10. Cookies & Tracking
We use essential cookies and local storage for authentication and session management. We do not use third-party advertising trackers. Analytics data, if collected, is used solely for improving the Service and is not shared with advertisers.
11. International Users
The Service is hosted in the United States. If you access the Service from outside the U.S., your data may be transferred to and processed in the United States. By using the Service, you consent to this transfer. We take reasonable steps to ensure your data receives adequate protection regardless of where it is processed.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy, contact us at:
Clock Deck LLC
Email: support@clockdeck.com